The SSO Wall of Shame
sso.tax
sso.tax
Of the top of my head I can think of Mapbox and AWS where it’s free. Atlassian charges $4/month covering all their products (cheap if you use two or more).
Any more good examples?
We flat up wont do 2/3rds of the asks you listed, but just getting it wired up & going, providing some basic debugging to make it go... we really are apes with hammers trying to pound these systems into going, have little idea what we're doing, & are way undertooled. It feels like super complex tech that requires very specific expertise to wrangle.
That said, I think this site is a great & wonderful & moral cause & I support this wall of shame fully. It just needs to be there, as annoying as it is.
Why must everyone suffer the outrageous 'tax' if most are just using the same top 2-3 providers anyway.
I used to work for Ubisoft, a 20,000+ person company, and SSO was used for almost nothing because it was considered far too costly.
conversely: I worked for a Tencent owned studio recently and they used SSO for everything, it was amazing, until the Okta breach (and response, which is worse than the breach itself)
Now I'm at a startup, and the sentiment is the same as Ubisoft; better off buying a lastpass subscription than paying for SSO, even though there's many drawbacks to that approach.
At work we use PingID which is not very expensive compared to industry standard ones like Okta. But it's very poor in my opinion. It seems they're always lagging years behind competitors in terms of features.
The problem is not the hosting of it; it's that nothing will integrate with your iDP, so you can't use your personal keycloak/traefik instance with, say, your github or gitlab profile.
Mozilla Persona was a good idea of handling this[0] but sadly was retired.
I don't care about integrating with online services, it's more for my home stuff. I self-host everything of importance anyway. And most external services only integrate with IDPs on their most expensive corporate plans anyway (unless they integrate with Google, Apple or Microsoft consumer accounts which I don't use).
Kinda looking for a personal PKI as well (which can overlap a lot with IDP) but I'll see what these can provide. I looked about 2 years ago and didn't come across either of them.
[0] https://github.com/mesosphere/traefik-forward-auth [1] https://brianturchyn.net/traefik-forwardauth-support-with-ke...
The most recent version of Keycloak jettisons JBoss in favor of Quarkus and everything about it is roundly better as a result. I'd been running a version from 2018 until this month!
Pardon the annoying analogy but it's like Java programmers clutching at control which is undermined by not only the language but the JVM itself.
"Java is secure by design.": I get the full stop. You don't want me to say this. But it's not secure in practice.
SaaS vendors all have a vetted list of SSO providers (even if there's only one option in the list). Honestly I'd love to know how SSO vendors market themselves to app vendors. I've never worked with this in a corporate environment.
What I do know is that as a SaaS user, I'd like to be able to provide my own authentication or second factor and that's never in the signup.
> The right way to think of the "SSO tax" (where companies charge extra for security features) is "You are being offered a dual use product backed by a strong engineering team for far less than it would otherwise cost, with sophisticated enterprises picking up the slack."
https://twitter.com/patio11/status/1481293027331440640
Further down the thread:
> SSO is a segmentation lever, and a particularly powerful one because (as @tqbf notes), everybody in the sophisticated-and-well-monied segment is increasingly forced to purchase it.
> In this it is like asking a vendor for HIPAA-compliant services. Yes, enjoy 2X on the invoice.
https://twitter.com/patio11/status/1481293496506253321
I quote tweeted it and said:
> An interesting question is if/when will SSO become so prevalent that it won't be a point of pricing leverage any more?
> After all you used to have to pay (a fair bit) for SSL certs, until the industry recognized the benefits of them being widespread.
https://twitter.com/mooreds/status/1481300034448760842
I fully expect at some point in the future SSO will be as prevalent as SSL support is now.
I'm currently using Firebase which supports sign-in with Microsoft, but not sure if that's technically the same as SSO.
If you want something more permanant Keycloak is probably your best bet. I'm not aware of any other truly free ones
* FusionAuth has a community edition which is free as long as you host it yourself and comply with the license ( https://fusionauth.io/license-faq#3 ). Free as in beer, at least. (Full disclosure, I work for FusionAuth.) Here's our SSO guide: https://fusionauth.io/docs/v1/tech/guides/single-sign-on
* If you want a SaaS solution, Cognito is an option, as is Azure AD B2C. They have good free tiers, as long as you don't want SAML integration (for Cognito, you're charged after 50 users).
* If you want to run your own, you could conceivably cobble something together on whatever tech stack you run. Ruby on rails, java/spring, django/python all have libraries which can be used to build OIDC servers. Then it's a question of setting up the sessions correctly. Here's an example I found via googling: https://tushartuteja.medium.com/a-simple-single-sign-on-sso-...
* As the parent comment mentioned, Keycloak is an option as well.
Is AGPL or one of those new licenses like the BSL not sufficient to prevent this sort of thing?
The full legalese is here: https://fusionauth.io/license
Both Microsoft Azure AD and JumpCloud have free plans you can use for testing.
https://developer.microsoft.com/en-us/microsoft-365/dev-prog...
However at work it's a pain managing users on paid services, and getting access can sometimes take days. SSO makes a lot more sense for corporate accounts.